Activity timeline
T1571 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 76 reports, and 214 of the 215 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1571 Non-Standard Port is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 215 of 2623 tracked threats (8.2%) to it; by severity that is 65 critical, 141 high, 9 medium.
Threats that use T1571 most often also use T1027 Obfuscated Files or Information (159 threats), T1082 System Information Discovery (154 threats), T1041 Exfiltration Over C2 Channel (130 threats), T1005 Data from Local System (128 threats), T1105 Ingress Tool Transfer (122 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
67 tracked threat actors appear in the threats that use T1571; the most frequent are APT38 (10), Sapphire Sleet (10), Stardust Chollima (9), UNC1069 (8), Contagious Interview (7).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1571.
Data sources
Telemetry that can reveal T1571, per MITRE ATT&CK.
- Network Traffic — Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 215 tracked threats that use T1571.
- BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances…high
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…high
- Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal…high
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt…high
- SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…high
- Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (CVE-2026-7273) Actively Exploited by Kapibala/Red…critical
- EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2high
- BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2high
- Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkitcritical
- Smishing Triad "Outsider" Operator: JWR Phishing Kit's AES-256-CTR WebSocket Exfiltration Cockpithigh
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malwarecritical
- Tropic Trooper Spear-Phishing Campaign Uses LNK Loader, DLL Side-Loading via Signed McAfee Binary, and…high
- StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active Exploitationcritical
- Attacks in Korea Deploy Radmin and UltraVNC for Remote Control, Followed by Proxy/VPN Tools for…high
- Silver Fox Counterfeit Installer Campaign Delivers Persistent, Self-Protecting Implant via Spoofed Vendor…high
- ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloadinghigh
- Auto-Color Linux Backdoor Reverse-Engineered: Root-Level LD_PRELOAD Persistence and Encrypted C2high
- Fake Beijing Institute of Technology Resume Lure Delivers SNOWLIGHT Shellcode and Fileless VShell RAT to…high
- TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and Indiahigh
- TonRAT Phishing Campaign Impersonating Booking.com Targets Hotel Industryhigh
- SLEEPWALKER: Passive-Trigger Windows Backdoor Masquerading as dpapi.dll via ERAAgent.exe Side-Loadingmedium
- Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption…high
- JA4H Fingerprinting Detects Sliver C2 Deployed via Chained PAN-OS CVE-2024-0012/CVE-2024-9474 Exploitationhigh
- CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability (CVE-2025-62593) by…critical
- Rust Supply Chain Attack on arrayref: Malicious Crate Versions with DPRK-Linked Backdoorcritical
- Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimihigh
- Researcher Demonstrates Full C2 Inside ChatGPT Secure Sandbox via Chained Attack Techniques at Black Hat USA…high
- ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Modelscritical
- NightmareEclipse Coordinated Disclosure Breach Campaign: 9+ Windows Zero-Days (CVE-2026-33825…critical
- Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoorhigh
Detection coverage
Threadlinqs maintains 372 detection rules mapped to T1571 (SPL 153, KQL 102, Sigma 117). Rule content is available to Blue tier accounts and above; this page shows counts only.